2026 CVE Vulnerabilities
56,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1227 | HIGH | 7 | 0.1% | Feb 11, 2026 | CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclo... |
| CVE-2026-1226 | HIGH | 7 | 0.1% | Feb 11, 2026 | CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintende... |
| CVE-2026-0910 | HIGH | 8.8 | 0.5% | Feb 11, 2026 | The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13... |
| CVE-2026-1458 | HIGH | 7.5 | 0.4% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18... |
| CVE-2026-1456 | HIGH | 7.5 | 0.4% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 th... |
| CVE-2026-0958 | HIGH | 7.5 | 0.4% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 1... |
| CVE-2026-1560 | HIGH | 8.8 | 9.1% | Feb 11, 2026 | The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to... |
| CVE-2026-1507 | HIGH | 8.7 | 0.3% | Feb 10, 2026 | The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely c... |
| CVE-2026-21349 | HIGH | 7.8 | 0.1% | Feb 10, 2026 | Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2026-25613 | HIGH | 7.1 | 0.2% | Feb 10, 2026 | An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo... |
| CVE-2026-25610 | HIGH | 7.1 | 0.2% | Feb 10, 2026 | An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints. |
| CVE-2026-25506 | HIGH | 7.8 | 0.3% | Feb 10, 2026 | MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can ... |
| CVE-2026-21353 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resul... |
| CVE-2026-21352 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr... |
| CVE-2026-21347 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could re... |
| CVE-2026-21346 | HIGH | 7.8 | 0.1% | Feb 10, 2026 | Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arb... |
| CVE-2026-21345 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft... |
| CVE-2026-21344 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft... |
| CVE-2026-21343 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft... |
| CVE-2026-21342 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-21341 | HIGH | 7.8 | 0.1% | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-1850 | HIGH | 7.5 | 0.2% | Feb 10, 2026 | Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash. |
| CVE-2026-1849 | HIGH | 7.5 | 0.3% | Feb 10, 2026 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents... |
| CVE-2026-1848 | HIGH | 8.2 | 0.3% | Feb 10, 2026 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i... |
| CVE-2026-1847 | HIGH | 7.5 | 0.2% | Feb 10, 2026 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now